Internal sources and documents seen by Guardian reporters indicate that advanced persistent threat (APT) hacker groups working for Russia and China have likely had sleeper malware spread throughout the UK nuclear site's IT systems since at least 2015.

